RE: [squid-users] NTLM and the dreaded popup

From: Chemolli Francesco (USI) <ChemolliF@dont-contact.us>
Date: Tue, 12 Mar 2002 09:21:40 +0100

> Does anyone know how to get rid of the popup asking for
> username/password/domain when using NTLM?
>
> I've tried to impliment NTLM using 2.5pre3 and it works MOST
> of the time
> however every few minutes or so it keeps poping back.
>
> I've played with the parameters to extend them way beyond
> reasonable eg
> auth_param ntlm children 20
> auth_param ntlm max_challenge_reuses 500
> auth_param ntlm max_challenge_lifetime 10 minutes
>
> But this seems to make little difference...(do you need to
> restart squid
> as opposed to reload for param changes to take effect?)
>
> Any hints as to where I should look?

This depends on an inherent unreliability in the SMBSessSetup mechanism
the NTLMSSP helper uses to authenticate. You either need
the helper-fail-open option, or to try the winbind auth program
(look at http://devel.squid-cache.org/, tag "ntlm") which requires an
alpha-level samba to run on the squid host.

-- 
	ing. Francesco Chemolli
	Unicredit Servizi Informativi
Received on Tue Mar 12 2002 - 01:22:54 MST

This archive was generated by hypermail pre-2.1.9 : Tue Dec 09 2003 - 17:06:49 MST